Description: | Description: The remote host is missing an update to libmikmod announced via advisory USN-995-1.
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS Ubuntu 9.04 Ubuntu 9.10
Details follow:
It was discovered that libMikMod incorrectly handled songs with different channel counts. If a user were tricked into opening a crafted song file, an attacker could cause a denial of service. (CVE-2007-6720)
It was discovered that libMikMod incorrectly handled certain malformed XM files. If a user were tricked into opening a crafted XM file, an attacker could cause a denial of service. (CVE-2009-0179)
It was discovered that libMikMod incorrectly handled certain malformed Impulse Tracker files. If a user were tricked into opening a crafted Impulse Tracker file, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-3995, CVE-2010-2546, CVE-2010-2971)
It was discovered that libMikMod incorrectly handled certain malformed Ultratracker files. If a user were tricked into opening a crafted Ultratracker file, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-3996)
Solution: In general, a standard system update will make all the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-995-1
Risk factor : Critical
CVSS Score: 9.3
|